SHADOW#REACTOR Malware Builds Remcos RAT via Text Files
ID: cb4cb9f8-302f-5f12-bdba-f0dbe4b86686
STIX ID: report--cb4cb9f8-302f-5f12-bdba-f0dbe4b86686
Feed Name: securityonline.info
Threat Score
Securonix research identifies SHADOW#REACTOR, a sophisticated loader framework that avoids disk-based artifacts by retrieving fragmented text payloads, reconstructing and decoding them in memory via a .NET Reactor-protected assembly, and using legitimate Windows binaries (wscript.exe, MSBuild.exe) to deploy the Remcos RAT at scale; the campaign appears indiscriminate, financially motivated, and designed to provide initial access for further criminal activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
